본문으로 건너뛰기

보안 및 책임 있는 사용

AI가 신뢰할 수 없는 데이터를 다루거나 작업을 수행하기 시작하면 더는 무시할 수 없는 안전 모델입니다. 프롬프트 인젝션, 에이전트 보안, 책임 있는 사용을 다룹니다.

Invisible-Comment MCP Attacks & the Confused-Deputy PR Reviewer

On July 21, 2026 Manifold Security disclosed that Microsoft's official Azure DevOps MCP server ships without spotlighting on repo_get_pull_request_by_id — letting an attacker plant an HTML comment in a PR description that is invisible in the web UI but delivered verbatim to any AI agent that reviews it. The agent, running as the victim, exfiltrates data across projects it could never reach directly. Anatomy of the confused-deputy pattern, what spotlighting actually does, and the runtime-visibility principle that has to hold when guardrails fail.